--- David Irvine <[EMAIL PROTECTED]> wrote:
--------------------------------- Many thanks for a fantastic explanation and for taking the time tohelp me. I was just reading some docs there pointing me to this but youhave saved me a good few hours. I will search out info for python info on PBKDF2 many thanks for that.Just quickly though in point 3 does that mean I should use ECB mode ornot if I am going to split the file and send two parts to differentlocations? Girish: You should avoid ECB mode at all costs. Always go for CBC mode. ECB mode is just too easy to crack. I will try to give you an intuitive explanation of the difference bet CBC and ECB. In ECB , each block of the file is encrypted independently. So crackers can very easily correlate cipher data and launch a chosen ciphertext attack or some such. But in CBC mode, this is made very difficult by virtue of the fact that each successive plaintext block is not only encrypted with the secret key schedule, but also X-ORed with the ciphertext of the previous block. This ensures that the "diffusion" part of block ciphering is really thorough. After all encryption is nothing but confusion and diffusion... Feel free to ask whatever basic questions you have. :-) Also don't get too hung up with IV. It is enough if you are able to generate a secret key with good entropy. All the best! regards, Girish __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [EMAIL PROTECTED]
